CVE-2012-2982
CVE-2012-2982
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 19
githubgithub.com/JohnHammond/CVE-2012-2982★ 42githubgithub.com/cd6629/CVE-2012-2982-Python-PoC★ 5githubgithub.com/0xTas/CVE-2012-2982★ 3githubgithub.com/OstojaOfficial/CVE-2012-2982★ 2githubgithub.com/Gvmyz/CVE-2012-2982_Python★ 1githubgithub.com/JRrooot/CVE-2012-2982-Webmin-RCE★ 1githubgithub.com/elliotosama/CVE-2012-2982★ 0githubgithub.com/SieGer05/CVE-2012-2982-Webmin-Exploit★ 0githubgithub.com/lpuv/CVE-2012-2982★ 0githubgithub.com/SincIDK/CVE-2012-2982-Exploit-Script★ 0githubgithub.com/boriitoo/CVE-2012-2982★ 0githubgithub.com/marinovharisan/Webmin-1.580---file-show.cgi-Manual-Remote-Command-Execution-Non-Metasploit-★ 0githubgithub.com/CpyRe/CVE-2012-2982★ 0githubgithub.com/Ari-Weinberg/CVE-2012-2982★ 0githubgithub.com/varppi/CVE-2012-2982★ 0githubgithub.com/blu3ming/CVE-2012-2982★ 0githubgithub.com/0xF331-D3AD/CVE-2012-2982★ 0githubgithub.com/Shadow-Spinner/CVE-2012-2982_python★ 0exploitdbwww.exploit-db.com/exploits/21851não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://americaninfosec.com/research/index.htmlhttps://github.com/webmin/webmin/commit/1f1411fe7404ec3ac03e803cfa7e01515e71a213http://www.americaninfosec.com/research/dossiers/AISG-12-001.pdfhttp://www.kb.cert.org/vuls/id/788478http://www.securitytracker.com/id?1027507http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf